AI Hasn’t Sparked a DeFi ‘Hackpocalypse,’ Dragonfly Partner Says
Dragonfly partner Haseeb Qureshi says AI has not caused a DeFi ‘hackpocalypse’; incidents rose but the median hack size fell below $500,000 in 2026.
Dragonfly managing partner Haseeb Qureshi said artificial intelligence has not produced a DeFi “hackpocalypse.” He noted that while the number of incidents this year reached a record high, the median loss per hack has dropped to under $500,000.
Qureshi compared 2026 with 2025, when the median hack size exceeded $2 million. He pointed to several outsized breaches when explaining year-to-year differences, including a $1.4 billion theft from Bybit in February 2025 and large exploits affecting Drift Protocol and KelpDAO in April 2026. Excluding months with those large incidents, the average monthly value stolen in 2026 is lower than in 2025.
Industry-wide data that includes centralized exchanges, wallet compromises and phishing shows volatile monthly totals. Losses from crypto hacks surged in April 2026 to roughly $644 million, while February 2025 reached about $1.46 billion following the Bybit breach.
Blockchain security firm CertiK reported that losses from cryptocurrency hacks fell 46.8% year-on-year to $1.32 billion in the first half of 2026. CertiK also reported that more than 70% of second-quarter 2026 losses came from the KelpDAO and Drift Protocol incidents, which investigators have largely attributed to state-sponsored North Korean actors.
Qureshi described attackers using AI as concentrating on smaller projects and abandonware, rather than targeting well-defended, larger protocols. He said larger DeFi platforms have strengthened defenses, while undermaintained projects offer easier paths for exploitation.
OpenZeppelin founder Manuel Aráoz described the sector as ‘all of DeFi unsafe,’ citing the growing ability of AI coding agents to identify smart contract vulnerabilities.
Security researchers continue to track activity linked to state-backed groups. TRM Labs has estimated that North Korean-linked actors have stolen more than $6 billion in cryptocurrency since 2017. CertiK’s analysis emphasized that a small number of large incidents account for a large share of the industry’s dollar-denominated losses.
Experts and security firms say automated tools and targeted campaigns by state-backed actors are factors to monitor, particularly for smaller and poorly maintained protocols.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.







